CVE-2018-0640

HIGH

Aterm HC100RC Firmware < 1.0.1 - Authenticated Buffer Overflow via netWizard.cgi Parameters

Title source: llm
STIX 2.1

Description

Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_jvn
https://jvn.jp/en/jp/JVN84825660/index.html

Scores

CVSS v3 7.2
EPSS 0.0180
EPSS Percentile 75.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
nec/aterm_hc100rc_firmware < 1.0.1
Published Jan 09, 2019
Tracked Since Feb 18, 2026